CVE-2025-46528: WordPress Availability Calendar plugin <= 0.2.4 - Cross Site Request Forgery (CSRF) Vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in Steve Availability Calendar allows Stored XSS. This issue affects Availability Calendar: from n/a through 0.2.4.
Other sources
Cross-Site Request Forgery (CSRF) vulnerability in Steve Availability Calendar availability allows Stored XSS.This issue affects Availability Calendar: from n/a through <= 0.2.4.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-46528?
CVE-2025-46528 has a high severity rating due to its potential for Stored XSS via CSRF attacks.
How do I fix CVE-2025-46528?
To fix CVE-2025-46528, update the Steve Availability Calendar plugin to the latest version beyond 0.2.4.
What types of applications are affected by CVE-2025-46528?
CVE-2025-46528 affects the Steve Availability Calendar and WordPress Availability Calendar up to version 0.2.4.
What risks are associated with CVE-2025-46528?
The risks associated with CVE-2025-46528 include unauthorized actions being performed on behalf of authenticated users.
Is user data at risk due to CVE-2025-46528?
Yes, user data may be at risk if attackers exploit the stored XSS vulnerability enabled by CVE-2025-46528.